TY - GEN
T1 - LIReDroid
T2 - 15th Asia-Pacific Symposium on Internetware, Internetware 2024
AU - Wang, Yin
AU - Fan, Ming
AU - Zhang, Xicheng
AU - Shi, Jifei
AU - Qiu, Zhaoyu
AU - Wang, Haijun
AU - Liu, Ting
N1 - Publisher Copyright:
© 2024 ACM.
PY - 2024/7/24
Y1 - 2024/7/24
N2 - Malicious Android applications often employ covert behaviors to exfiltrate sensitive data, thereby compromising user privacy. Traditional detection techniques predominantly utilize static analysis of the source code to detect such sensitive behaviors, yet they are frequently plagued by elevated false positive rates. While dynamic analysis methods offer greater precision, they contend with the challenge of limited coverage. This paper introduces LIReDroid, a hybrid testing approach that aims to replicate sensitive behaviors identified in static analysis call chains. LIReDroid firstly analyze the application's static invocation chain. Then LIReDroid devises a prompt word model for the generation of test instructions and injection script code. Ultimately, sensitive API call chains are dynamically invoked through code injection, with their activation being meticulously recorded. We presented preliminary experimental results to substantiate the efficacy of LIReDroid. Given these results, we outline future research directions for LIReDroid.
AB - Malicious Android applications often employ covert behaviors to exfiltrate sensitive data, thereby compromising user privacy. Traditional detection techniques predominantly utilize static analysis of the source code to detect such sensitive behaviors, yet they are frequently plagued by elevated false positive rates. While dynamic analysis methods offer greater precision, they contend with the challenge of limited coverage. This paper introduces LIReDroid, a hybrid testing approach that aims to replicate sensitive behaviors identified in static analysis call chains. LIReDroid firstly analyze the application's static invocation chain. Then LIReDroid devises a prompt word model for the generation of test instructions and injection script code. Ultimately, sensitive API call chains are dynamically invoked through code injection, with their activation being meticulously recorded. We presented preliminary experimental results to substantiate the efficacy of LIReDroid. Given these results, we outline future research directions for LIReDroid.
KW - Android Application Security
KW - Large Language Model
KW - Sensitive Behavior Reproduction
KW - Test Case Generation
UR - https://www.scopus.com/pages/publications/85200901547
U2 - 10.1145/3671016.3671404
DO - 10.1145/3671016.3671404
M3 - 会议稿件
AN - SCOPUS:85200901547
T3 - ACM International Conference Proceeding Series
SP - 81
EP - 84
BT - 15th Asia-Pacific Symposium on Internetware, Internetware 2024 - Proceedings
PB - Association for Computing Machinery
Y2 - 24 July 2024 through 26 July 2024
ER -